You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
gitea/routers/web
Lunny Xiao b01dce2a6e
Allow render HTML with css/js external links (#19017)
* Allow render HTML with css/js external links

* Fix bug because of filename escape chars

* Fix lint

* Update docs about new configuration item

* Fix bug of render HTML in sub directory

* Add CSP head for displaying iframe in rendering file

* Fix test

* Apply suggestions from code review

Co-authored-by: delvh <dev.lh@web.de>

* Some improvements

* some improvement

* revert change in SanitizerDisabled of external renderer

* Add sandbox for iframe and support allow-scripts and allow-same-origin

* refactor

* fix

* fix lint

* fine tune

* use single option RENDER_CONTENT_MODE, use sandbox=allow-scripts

* fine tune CSP

* Apply suggestions from code review

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>

Co-authored-by: delvh <dev.lh@web.de>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
3 years ago
..
admin Refactor git module, make Gitea use internal git config (#19732) 3 years ago
auth Adding button to link accounts from user settings (#19792) 3 years ago
dev Move user related model into models/user (#17781) 3 years ago
events Improve Stopwatch behavior (#18930) 3 years ago
explore In code search, get code unit accessible repos in one (main) query (#19764) 3 years ago
feed Add `ContextUser` to http request context (#18798) 3 years ago
healthcheck Update go-chi/cache to utilize Ping() (#19719) 3 years ago
misc Fix panic in team repos API (#19431) 3 years ago
org Move issues related files into models/issues (#19931) 3 years ago
repo Allow render HTML with css/js external links (#19017) 3 years ago
user Remove tab/TabName usage where it's not needed (#19973) 3 years ago
auth.go Remove legacy `+build:` constraint (#19582) 3 years ago
auth_windows.go Let web and API routes have different auth methods group (#19168) 3 years ago
base.go Update base.go (#19739) 3 years ago
goget.go Refactor legacy `unknwon/com` package, improve golangci lint (#19284) 3 years ago
home.go Renamed ctx.User to ctx.Doer. (#19161) 3 years ago
metrics.go Update HTTP status codes to modern codes (#18063) 3 years ago
nodeinfo.go Add nodeinfo endpoint for federation purposes (#16953) 4 years ago
swagger_json.go Refactor routers directory (#15800) 4 years ago
web.go Allow render HTML with css/js external links (#19017) 3 years ago
webfinger.go Move almost all functions' parameter db.Engine to context.Context (#19748) 3 years ago